Privacy & Data · European Union · GDPR Enforcement

How to Complain About a Multinational Tech Company Under the GDPR One-Stop-Shop

A tech company may have its EU headquarters in Ireland or Luxembourg while you live elsewhere. The GDPR's One-Stop-Shop can coordinate the regulators involved — but it is not a private EU-wide court and it does not guarantee a fixed resolution date.

Start With Article 77: Complain to a Supervisory Authority

Article 77 GDPR gives a data subject the right to lodge a complaint with a supervisory authority, in particular in the Member State of habitual residence, place of work or place of the alleged infringement.

That means a consumer does not normally have to travel to Ireland simply because the platform's EU controller is established there.

When One-Stop-Shop Enters the Picture

For cross-border processing, the GDPR's cooperation mechanism can identify a lead supervisory authority (LSA) while other authorities act as concerned supervisory authorities (CSAs). The EDPB describes the workflow as: complaint or investigation → LSA inquiry → draft decision → CSA review → final decision, with the EDPB's consistency mechanism available if authorities cannot resolve a relevant disagreement.

The authority with which the individual lodged the complaint communicates the decision to the complainant.

Do Not Assume the Company Headquarters Decides the Authority for Every Case

The One-Stop-Shop applies to qualifying cross-border processing. Some processing may be local, and some complaints may not fall within the mechanism. The identity of the appropriate authority must be assessed from the controller, establishment, processing activity and cross-border effects.

What About Deadlines?

The GDPR gives individuals a right to an effective remedy against a supervisory authority under Article 78, but there is no simple EU rule saying a regulator must finish every One-Stop-Shop complaint within a fixed number of months.

Practical follow-up is therefore evidence-based: keep the complaint reference, acknowledgement, requests for information and substantive communications. If a decision is issued and you believe it is deficient, examine the national judicial-review or appeal route available under the relevant law.

How to Make the Complaint Stronger

  1. Identify yourself and the controller precisely.
  2. Explain the processing and the GDPR right or obligation you say was infringed.
  3. Attach relevant correspondence and evidence.
  4. State what you asked the company to do before complaining.
  5. Explain why the response was inadequate.
  6. Keep the complaint reference and all subsequent communications.

What Happens if Another Regulator Is the Lead Authority?

Your complaint may be coordinated with the lead authority and other concerned authorities. The national authority that received your complaint remains important to the communication process even when another authority performs the main investigation.

What This Means Practically

Sources